← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Redhat
2Fedora
Libvirt
Jun 17, 2026
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-adm...Show more
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.Show less
5Canonical
DebianFedoraproject+2 more
7Backports Sle
Debian LinuxFedora+4 more
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
4Canonical
DebianFedoraproject+1 more
5Debian Linux
FedoraSdl2 Image+2 more
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX...Show more
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraFreeimage+1 more
Jun 17, 2026
May 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
6Artifex
CanonicalDebian+3 more
6Debian Linux
Enterprise LinuxFedora+3 more
Jun 17, 2026
May 16, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have acces...Show more
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.Show less
4Debian
FedoraprojectHeimdal Project+1 more
5Backports Sle
Debian LinuxFedora+2 more
Jun 17, 2026
May 15, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
5Fedoraproject
HpeNetapp+2 more
6Clustered Data Ontap
Data OntapFedora+3 more
Jun 17, 2026
May 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NTP through 4.2.8p12 has a NULL Pointer Dereference.
5Canonical
DebianFedoraproject+2 more
15Debian Linux
Enterprise LinuxEnterprise Linux Desktop+12 more
Jun 17, 2026
May 15, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the...Show more
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.Show less
3Fedoraproject
OpensuseSylabs
4Backports
FedoraLeap+1 more
Jun 17, 2026
May 14, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit fil...Show more
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.Show less
3Fedoraproject
OpensuseRust Lang
3Fedora
LeapRust
Jun 17, 2026
May 13, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is ove...Show more
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.Show less
6Canonical
DebianFedoraproject+3 more
12Debian Linux
Enterprise LinuxEnterprise Linux Eus+9 more
Jun 17, 2026
May 10, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a...Show more
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.Show less
5Debian
DrupalFedoraproject+2 more
5Debian Linux
DrupalFedora+2 more
Jun 17, 2026
May 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as de...Show more
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.Show less
3Dovecot
FedoraprojectOpensuse
3Dovecot
FedoraLeap
Jun 17, 2026
May 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
3Dovecot
FedoraprojectOpensuse
3Dovecot
FedoraLeap
Jun 17, 2026
May 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
3Fedoraproject
KdeOpensuse
4Backports
FedoraKauth+1 more
Jun 17, 2026
May 7, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with...Show more
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
May 3, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.Show less
3Debian
FedoraprojectFilezilla Project
3Debian Linux
FedoraFilezilla Client
Jun 17, 2026
Apr 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
4Canonical
FedoraprojectNetapp+1 more
7Cn1610 Firmware
FedoraHci Management Node+4 more
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.Show less
7Canonical
DebianFedoraproject+4 more
14Active Iq Unified Manager For Vmware Vsphere
Cn1610 FirmwareDebian Linux+11 more
Jun 17, 2026
Apr 25, 2019
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other...Show more
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.Show less
6Canonical
DebianFedoraproject+3 more
13Active Iq Unified Manager For Vmware Vsphere
Cn1610 FirmwareDebian Linux+10 more
Jun 17, 2026
Apr 24, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administra...Show more
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.Show less